Security Advisory
CVE-2008-6120
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
SQL injection vulnerability in profile_comments.php in SocialEngine (SE) 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the comment_secure parameter.